{"serviceIdentification":{"providerName":"Bland AI","serviceName":"Bland","serviceAcronym":"Bland","serviceDescription":"Bland is an enterprise voice AI platform for building, deploying, and operating AI phone agents at scale. Bland runs its own speech and language models, so customer calls are not sent to third-party frontier model providers. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models within Bland’s boundary.","certificationType":"20x","fedRampPackageId":"FR2628647242","ueiNumber":"","website":"https://www.bland.ai","logo":"https://www.bland.ai/images/bland-logo.svg"},"serviceProperties":{"serviceType":["PaaS"],"deploymentModel":"Government-Only Cloud","digitalIdentityLevel":"IAL: customer/agency-managed or not performed by Bland; AAL2 for Bland-managed administrative authentication where MFA is enforced; FAL2 where federated SSO is configured","businessCategory":["Artificial Intelligence (AI)","Contact Center"],"trustCenter":{"repositoryType":["Trust Center"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Bland FedRAMP Trust Center. FedRAMP package and security documentation for federal agencies and recognized assessors.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},"secureConfigurationGuidance":{"repositoryType":["Secure Configuration Guidance"],"url":"https://trust.bland-gov.com/resources?s=8udmre29tx8im63a7l6bhw&name=bland-ai-secure-configuration-guide.pdf","repositoryDescription":"Bland AI secure configuration guide: hardening and configuration guidance for operating Bland securely (SCG-CSO-RSC).","authenticationRequired":false},"additionalRepositories":[{"repositoryType":["Documentation Catalog"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Catalog of all policies and procedures (name, version, date updated, summary). Available on the Trust Center in human-readable and machine-readable format.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Quarterly Certification Progress Report"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Detailed quarterly roadmap: completed milestones, current work, upcoming work, and assessment timeline.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Assessment Deadline"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Official statement of work from Prescient Security documenting Bland’s commitment to a Class C assessment within the next 24 months.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Vulnerability Reporting"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Vulnerability detection and response reporting published as FedRAMP Certification Data: the monthly human-readable report required by VER-TFR-MHR and its machine-readable companions for VER-RPT-VDT and VER-RPT-AVI. Governed by the Bland Vulnerability Management Plan and the Bland VDR Reporting Procedure.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Historical Vulnerability Activity"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Machine-readable historical vulnerability evaluation and reporting activity for automated retrieval (VER-TFR-MRH), with the retrieval design, access model, and schedule set out in the Bland Historical Vulnerability Activity Retrieval Statement. Partially implemented; published as a periodic snapshot pending the authenticated retrieval endpoint.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Incident Reporting"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Where Bland publishes Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents (IEC-CSO-IIR, IEC-CSO-OIR, IEC-CSO-FIR) in human-readable and machine-readable form.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."},{"repositoryType":["Significant Change Notifications"],"url":"https://trust.bland-gov.com/","repositoryDescription":"Where Bland publishes Significant Change Notifications and related audit records (SCN-CSO-INF, SCN-CSO-HRM) in human-readable and machine-readable form.","authenticationRequired":true,"accessRequestInstructions":"Use the \"Request access\" button on the Trust Center; access can be reclaimed with \"Reclaim access\". Questions: fedramp@bland.ai."}],"nextOngoingCertificationReportDate":"2026-10-30"},"contactInformation":[{"contactType":"Security","contactName":"Bland FedRAMP","contactEmail":"fedramp@bland.ai"},{"contactType":"Sales","contactName":"Bland Federal Sales","contactEmail":"sales@bland.ai"}],"certifiedServices":[{"serviceName":"Voice agents","serviceDescription":"AI phone agents that answer inbound calls and place outbound calls, hold natural spoken conversations, and act on what the caller needs. Each agent follows a configurable conversation pathway, a decision tree that interprets the caller’s intent and then routes the call or takes an action such as scheduling, sending follow-ups, taking payments, answering questions from an approved knowledge base, or escalating to a person. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models inside Bland’s boundary.","dateAvailable":"2026-07-13"},{"serviceName":"SMS","serviceDescription":"Programmatic two-way text messaging driven by the same pathway logic as voice agents. Agents send and respond to messages for notifications, reminders, status updates, and structured question-and-answer flows, triggering the same actions as a voice agent, such as scheduling, follow-ups, and record updates, over text rather than a call.","dateAvailable":"2026-07-13"},{"serviceName":"Chat","serviceDescription":"Web and in-app chat agents that run on the same conversation pathways and actions as voice and SMS, embedded in an agency’s web properties for self-service. Chat shares the rule sets, knowledge, and integrations of the other channels, so a constituent gets the same answers and outcomes no matter how they reach out.","dateAvailable":"2026-07-13"}],"thirdPartyInformationResources":{"certified":[{"name":"AWS GovCloud","fedRampCertifiedThirdPartyInformationResource":"F1603047866","useCase":"Cloud infrastructure hosting the Bland service."}],"nonCertified":[{"name":"Okta","provider":"Okta","website":"https://www.okta.com","useCase":"Identity provider for Bland-managed administrative authentication."},{"name":"Twilio","provider":"Twilio","website":"https://www.twilio.com","useCase":"Telephony carrier connectivity (PSTN) for voice calls."}]},"x-bland":{"note":"CPO-CSO-MTD requires the responsible official, version, date and time of last update, and source of update in the Certification Package Overview. The official FedRAMP Certification Package Overview schema has no property for any of the four, so Bland carries them here. The schema does not set additionalProperties to false, so this validates. Re-check on each schema release.","certificationPackageOverviewMetadata":{"responsibleOfficial":{"name":"Juan Riojas","title":"Chief Information Officer","email":"fedramp@bland.ai"},"version":"1.3","lastUpdated":"2026-08-31T00:00:00Z","sourceOfUpdate":"Recorded 20x Class A Certification received 2026-08-25 (FedRAMP Marketplace FR2628647242; Type 20x, Path Program, Class A Pilot, phase Ongoing Certification) and the move to a Class C application, with the Prescient Security Class C assessment beginning 2026-09-01 and submission to follow in Q3. Corrected the next Ongoing Certification Report date to 2026-10-30. Removed Cloudflare from third-party information resources. Aligned the service description with the human-readable overview, cleared ueiNumber to blank per the schema’s guidance for an unassigned UEI, and added Trust Center repositories for vulnerability reporting (VER-TFR-MHR, VER-RPT-VDT, VER-RPT-AVI), historical vulnerability activity (VER-TFR-MRH), incident reporting (IEC-CSO-IIR/OIR/FIR), and significant change notifications (SCN-CSO-INF, SCN-CSO-HRM)."}}}